Privacy Policy
Effective Date: February 10, 2026
Last Updated: August 30, 2026
Your Privacy Matters
IANternet Media (“OpenAssist,” “we,” “us,” or “our”) operates OpenAssist.io, a managed deployment platform for OpenClaw AI agents. This Privacy Policy explains how we collect, use, share, and protect your personal information.
By using OpenAssist, you agree to the data practices described in this policy. If you do not agree, please do not use our Service.
1. INFORMATION WE COLLECT
1.1 Account Information
When you create an account, we collect:
- Email address (via Google OAuth or direct registration)
- Display name (from your Google profile or provided by you)
- Profile picture URL (from Google, optional)
- User ID (automatically generated by Supabase)
- Account creation date and last login timestamp
1.2 Subscription & Payment Data
To process payments, we collect:
- Payment information (processed and stored by Stripe—we never store full credit card numbers)
- Billing address (required by Stripe for payment processing)
- Subscription plan (Starter, Standard, or Pro)
- Subscription status (active, trial, inactive, canceled)
- Billing history (invoices, payment dates, amounts)
- Stripe Customer ID (to link your account with Stripe records)
Important: Credit card details are handled exclusively by Stripe (PCI-DSS Level 1 certified). We do not have access to your full card numbers.
1.3 Service Usage Data
To provide the OpenAssist dashboard and manage your agents, we collect:
- Tasks: Title, description, status, assigned agents, creation/completion timestamps
- Agents: Name, role, personality configurations (SOUL.md, IDENTITY.md), session keys
- Protocols: Workflow definitions, categories, steps, agent types
- Schedules: Cron expressions, task templates, execution logs, success/failure status
- Activity logs: Task status changes, agent actions, system events, timestamps
- Chat messages: Conversations between you and your OpenClaw agents
- Instance metadata: DigitalOcean droplet IDs, IP addresses, regions, plans, status (active/stopped/provisioning)
- Configuration files: HEARTBEAT.md, AGENTS.md, memory files (stored on your droplet)
1.4 API Keys & Credentials (Encrypted)
You provide API keys that we store securely:
- Anthropic/OpenAI API keys: Stored encrypted in your DigitalOcean droplet’s environment variables (we cannot decrypt or access them)
- DigitalOcean API token: Encrypted in Supabase, used to manage your droplets (create, start, stop, destroy)
- Cloudflare credentials (optional): If you use custom DNS, stored encrypted for DNS configuration
We do NOT:
- Store API keys in plain text
- Access your AI model API keys
- See your AI provider billing or usage data
1.5 Technical & Analytics Data
Automatically collected:
- IP address: For security, fraud prevention, and approximate geolocation
- Browser information: Type, version, language, user agent
- Device data: Type (desktop/mobile/tablet), operating system, screen resolution
- Cookies: Authentication session, preferences (see Section 9)
- Usage analytics: Via Google Analytics (see Section 1.6)
Location data:
- Geolocation: Approximate location inferred from IP address (city/country level, not precise GPS)
- Timezone: Browser timezone for scheduling features
- Droplet region: You manually select DigitalOcean regions (NYC, SF, Toronto, Amsterdam, Singapore, etc.)
1.6 Google Analytics
We use Google Analytics to understand how users interact with OpenAssist:
What Google Analytics collects:
- Page views and navigation paths
- Feature usage (which tabs/buttons are clicked)
- Session duration and bounce rates
- Anonymized demographic data (age range, gender, interests—not linked to your identity)
- Device and browser statistics
What Google Analytics does NOT collect:
- Your email address or personally identifiable information (PII)
- Chat message content or AI prompts
- Payment information or API keys
Your choices:
- Opt-out: Use our cookie consent banner to disable analytics
- Browser extension: Install Google Analytics Opt-out Browser Add-on
Data retention: Google Analytics data is retained for 26 months, then automatically deleted.
Google’s Privacy Policy: https://policies.google.com/privacy
1.7 Email Communications (Brevo)
We use Brevo (formerly Sendinblue) to send emails:
What Brevo processes:
- Your email address
- Display name
- Email engagement data (opens, clicks, bounces)
- Subscription preferences (marketing opt-in/opt-out)
Types of emails:
- Transactional (required): Welcome emails, billing notifications, password resets, security alerts
- Marketing (optional): Feature announcements, tips, newsletters, promotional offers
Brevo does NOT:
- Sell your data to third parties
- Send emails on our behalf without your consent (for marketing)
Brevo’s Privacy Policy: https://www.brevo.com/legal/privacypolicy/
1.8 Google Account Data (Google Drive & Google Ads)
Connecting a Google account is optional. Nothing in this section applies unless you choose to connect one, and you can disconnect at any time. We request the narrowest permissions each feature needs:
- Identity (openid, email): Your Google account’s email address, so the dashboard can show you which account is connected.
- Drive per-file access (drive.file): Reaches only the files OpenAssist itself creates and the files you explicitly select through a picker. It does not grant access to the rest of your Drive.
- Drive folder names (drive.metadata.readonly): Optional, and requested only if you press “Reconnect (expand scopes)” to browse your folder tree and set a default upload folder. It returns folder and file names and IDs — never file contents.
- Google Ads (adwords): Reads and manages the Google Ads accounts you choose to link, for the Google Ads app.
What we access and store:
- Google Drive: Listing files and folders, reading file metadata, downloading the contents of files you or your agent request, and uploading files your agent produces. File contents pass through our broker to your agent; we do not keep a copy in our database. If your agent saves a downloaded file, it is written to your own droplet’s disk, which is your storage and is destroyed with the droplet.
- Google Ads: The list of Ads accounts your Google login can reach, so that you can choose one; and, for the account you link, campaign, keyword, search-term and performance reporting. That reporting is cached in your account’s Google Ads tables in our database so the dashboard and your agent can query it without re-fetching from Google on every request.
- Credentials: Your Google refresh token, encrypted with AES-256-GCM before it is stored. Access tokens are minted server-side on demand and are never returned to your browser. Your droplet holds no Google credentials at all — it reaches Drive only through our broker, which authenticates the droplet and applies your account’s permissions.
How we use it: Only to operate the features you invoke — showing your Drive files in a picker, uploading what your agent generates, and producing the Google Ads reports and recommendations you ask for. Where answering your request requires an AI model, the content is processed by the AI provider configured for your instance: your own provider account when you supply the API key, or Anthropic through our gateway on credits-based plans.
We do NOT:
- Use Google user data to develop, improve, or train any AI or machine-learning model, generalized or otherwise
- Use Google user data for advertising, ad targeting, or building audiences
- Sell Google user data, or transfer it to data brokers or information resellers
- Read your Google user data as humans, except with your explicit permission (for example, when you ask us to investigate a specific problem), where necessary for security purposes such as investigating abuse, or where required by law
Revoking access and deletion:
- Disconnecting the integration in the dashboard revokes the refresh token at Google and deletes the stored credentials from our database.
- You can revoke OpenAssist independently at any time from your Google account’s permissions page: https://myaccount.google.com/permissions
- Removing the Google Ads app deletes its cached reporting for your account. Deleting your OpenAssist account removes everything described here, as set out in Section 4.
- Revoking access does not retroactively delete files already written to your own Google Drive, or files your agent already saved to your droplet.
Limited Use. OpenAssist’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
2. HOW WE USE YOUR INFORMATION
2.1 To Provide the Service
- Authentication: Log you in securely via Supabase and Google OAuth
- Agent deployment: Provision DigitalOcean droplets running OpenClaw
- Dashboard functionality: Display tasks, agents, protocols, schedules, and activity logs
- Chat interface: Route messages between you and your AI agents
- Data storage: Persist your data in Supabase (tasks, agents, configurations)
- DNS configuration: Set up secure Cloudflare domains for OpenClaw gateway access
- Billing: Process payments via Stripe and manage subscriptions
2.2 To Improve the Service
- Analytics: Understand feature usage and user behavior via Google Analytics
- Debugging: Identify and fix errors, crashes, and performance issues
- Optimization: Improve page load times, reduce API latency, enhance UX
- Feature development: Prioritize new features based on usage patterns
We do NOT:
- Read your chat messages or AI prompts for service improvement
- Train AI models on your data
- Use your agent outputs for any purpose beyond displaying them to you
2.3 To Communicate With You
Transactional emails (mandatory):
- Welcome email after signup
- Billing notifications (payment success/failure, subscription renewal)
- Security alerts (suspicious login attempts, password changes)
- Service updates (planned maintenance, critical bug fixes)
Marketing emails (optional, with your consent):
- Product updates and new features
- Tips and tutorials for using OpenAssist
- Promotional offers and discounts
- Blog posts and industry insights
You can opt out of marketing emails at any time via:
- Unsubscribe link in every marketing email
- Account settings in the dashboard
- Email preferences@openassist.io
Transactional emails cannot be opted out (required for account security and billing).
2.4 For Legal & Security Purposes
- Fraud prevention: Detect and prevent unauthorized access, payment fraud, abuse
- Terms enforcement: Investigate violations of our Terms of Service or Acceptable Use Policy
- Legal compliance: Respond to subpoenas, court orders, law enforcement requests
- Dispute resolution: Provide evidence in arbitration or legal proceedings
- Security monitoring: Log failed login attempts, unusual API usage, DDoS attacks
3. HOW WE SHARE YOUR INFORMATION
3.1 Third-Party Service Providers
We share data with trusted vendors who help us operate OpenAssist:
| Service | Data Shared | Purpose | Privacy Policy |
|---|---|---|---|
| Supabase | All service data (tasks, agents, auth sessions, activity logs) | Database & authentication | Supabase Privacy |
| DigitalOcean | Droplet configs, your DO API token, instance metadata | Agent hosting infrastructure | DigitalOcean Privacy |
| Vercel | Dashboard code, session data (via Supabase cookies) | Dashboard hosting (static files, serverless functions) | Vercel Privacy |
| Cloudflare | Domain names, DNS records, agent IP addresses | Secure DNS and DDoS protection | Cloudflare Privacy |
| Stripe | Email, name, billing address, payment method | Payment processing (PCI-DSS compliant) | Stripe Privacy |
| Google OAuth | Email, name, profile picture (optional) | Authentication (single sign-on) | Google Privacy |
| Google Analytics | IP address (anonymized), page views, device data | Usage analytics and insights | Google Privacy |
| Brevo | Email address, name, engagement data | Transactional and marketing emails | Brevo Privacy |
| Anthropic/OpenAI | Your prompts and AI outputs (via your API keys, not ours) | AI model inference (you control this data) | Anthropic Privacy / OpenAI Privacy |
All vendors:
- Are contractually obligated to protect your data
- May only use data to provide services to us (not for their own purposes)
- Must comply with applicable privacy laws (GDPR, CCPA)
3.2 Internal Access
Who at OpenAssist can access your data:
- Support team: To troubleshoot issues, answer questions, resolve billing disputes
- Engineering team: To debug errors, deploy infrastructure, monitor system health
- Authorized contractors: Subject to confidentiality agreements
Access controls:
- All access is logged and monitored
- No one can access your AI API keys (encrypted, inaccessible to us)
- We do NOT read your chat messages or prompts unless you explicitly share them for support purposes
3.3 We Do NOT Sell Your Data
OpenAssist does NOT:
- Sell personal information to third parties
- Share data with advertisers or data brokers
- Monetize your information beyond subscription fees
- Provide data to marketing companies for cross-site tracking
3.4 Legal Disclosures
We may disclose your information if required by law:
- Court orders, subpoenas, or legal process
- Law enforcement requests (with valid legal authority)
- National security demands (if legally compelled)
- Fraud investigations (cooperation with authorities)
We will:
- Notify you of legal requests (unless prohibited by law or court order)
- Challenge overly broad or unjustified requests
- Only disclose the minimum data required
3.5 Business Transfers
If OpenAssist is acquired, merged, or sells assets:
- User data may be transferred to the acquiring company
- You will be notified via email 30 days in advance
- The acquirer must honor this Privacy Policy (or obtain your consent for changes)
- You may delete your account before the transfer if you disagree
4. DATA RETENTION & DELETION
4.1 Active Accounts
While your account is active, we retain:
- All service data (tasks, agents, protocols, schedules, logs) indefinitely
- Chat history and activity logs
- Billing records (for tax and accounting)
4.2 Immediate Deletion Upon Cancellation
When you cancel your subscription or destroy an agent:
- DigitalOcean droplets are destroyed within minutes (all agent data lost permanently)
- Supabase data (tasks, agents, protocols, logs) is deleted immediately
- Dashboard access is revoked
- No recovery or grace period—deletion is instant and irreversible
Before canceling, you should:
- Export important data manually via the dashboard
- Download chat logs and task history
- Backup agent memory files via SSH (you have full root access to your droplet)
4.3 Backup Retention
Encrypted database backups (for disaster recovery) are retained for 90 days, then automatically purged.
Important:
- Backups are not accessible to you or our team after account deletion
- Used only for catastrophic system failures (not individual account recovery)
- Encrypted and stored securely
4.4 Legal & Financial Records
Permanently retained (required by law):
- Financial records (invoices, payment history): 7 years (tax/accounting compliance)
- Anonymized audit logs (fraud prevention): No personally identifiable information (PII)
4.5 Marketing Data (Brevo)
If you opt out of marketing emails:
- Your email remains in Brevo’s database (to honor opt-out preference)
- Marked as “unsubscribed” (no marketing emails sent)
- Deleted from Brevo within 90 days of account deletion
5. DATA SECURITY
5.1 Encryption
In Transit (TLS/HTTPS):
- All connections use TLS 1.3 encryption (HTTPS)
- Dashboard ↔ Supabase: Encrypted
- Dashboard ↔ DigitalOcean API: Encrypted
- Chat ↔ OpenClaw agent: Encrypted via HTTPS
- API calls to Stripe, Brevo, Google: Encrypted
At Rest (AES-256):
- Supabase: Database encryption (PostgreSQL with encryption at rest)
- DigitalOcean: Droplet volumes encrypted (provider-managed)
- Stripe: Payment data encrypted (PCI-DSS Level 1 compliant)
- API keys: Stored as encrypted environment variables (AES-256/bcrypt)
5.2 Access Controls
Authentication:
- OAuth 2.0 via Google (industry-standard security)
- Supabase Row Level Security (RLS) policies (users can only access their own data)
- Session tokens with automatic expiration (24-hour max)
- Password hashing (bcrypt with high cost factor)
Infrastructure security:
- Vercel: DDoS protection, automatic HTTPS, CDN caching, isolated serverless functions
- Cloudflare: DNS security, DDoS mitigation, Web Application Firewall (WAF)
- DigitalOcean: Network firewalls, isolated droplets, SSH key authentication
5.3 Application Security Measures
- Input validation: Prevent SQL injection, XSS attacks
- CSRF protection: Tokens on all state-changing requests
- Rate limiting: Prevent brute-force login attempts and API abuse
- Dependency updates: Regular security patches for libraries
- Code reviews: Manual and automated security audits
5.4 Monitoring & Incident Response
Proactive monitoring:
- Failed login attempt tracking (IP-based rate limiting)
- Anomaly detection (unusual API usage patterns, mass data exports)
- Real-time alerts for suspicious activity
- Regular security audits and penetration testing (as we scale)
Incident response plan:
- Detection: Automated alerts + manual monitoring
- Containment: Isolate affected systems, revoke compromised credentials
- Eradication: Patch vulnerabilities, remove threats
- Recovery: Restore from secure backups if needed
- Notification: Email affected users within 72 hours (GDPR requirement)
5.5 Data Breach Notification
If a security breach occurs affecting your data:
We will notify you within 72 hours via email with:
- What happened: Description of the breach (how it occurred, when discovered)
- What data was affected: Types of information compromised (email, tasks, etc.)
- What we’re doing: Steps to remediate the breach and prevent recurrence
- What you should do: Recommended actions (change passwords, rotate API keys, monitor accounts)
Regulatory notification:
- EU users: Notification to relevant Data Protection Authority (GDPR)
- California users: Notification per California Civil Code § 1798.82 (CCPA)
- Other jurisdictions: As required by applicable laws
No breach has occurred as of this policy’s effective date.
6. YOUR PRIVACY RIGHTS
6.1 Right to Access Your Data
You can access your data at any time:
Self-service (via dashboard):
- View all tasks, agents, protocols, schedules, activity logs
- Download chat history (manual export via UI)
- Access agent memory files via SSH (full root access to your DigitalOcean droplet)
Formal data access request:
- Email privacy@openassist.io with your registered email address
- We’ll provide a comprehensive data export (JSON/CSV format) within 30 days
What you’ll receive:
- Account information (email, display name, subscription status)
- Service usage data (tasks, agents, protocols, schedules, activity logs)
- Billing history (invoices, payment dates)
- Technical data (IP addresses, login timestamps)
Note: We cannot provide your AI API keys (encrypted, inaccessible to us).
6.2 Right to Delete Your Data
You can delete your data at any time:
Self-service deletion (immediate):
- Cancel subscription via dashboard settings → Agent destroyed + data deleted instantly
- Destroy individual agent instances → Droplet deleted, memory lost permanently
Full account deletion:
- Email privacy@openassist.io with subject line “Account Deletion Request”
- We’ll verify your identity (security questions or email confirmation)
- Account and all data deleted within 7 days
What gets deleted:
- All Supabase data (tasks, agents, protocols, logs, chat history)
- DigitalOcean droplets (agents destroyed)
- Dashboard access revoked
- Marketing email subscriptions (removed from Brevo)
What remains (legal requirements):
- Financial records (invoices, payment history) for 7 years (tax compliance)
- Anonymized audit logs (no PII) for fraud prevention
6.3 Right to Export Your Data (Data Portability)
You can export your data in machine-readable formats:
Self-service export:
- Dashboard allows downloading task lists, activity logs (JSON/CSV)
- SSH access to your droplet (full file system access to agent memory)
Formal export request:
- Email privacy@openassist.io
- We’ll provide a comprehensive data package within 30 days
- Formats: JSON, CSV (structured, easy to import elsewhere)
6.4 Right to Correct Your Data
Update inaccurate information:
Self-service:
- Edit display name, profile picture via account settings
- Update agent configurations, task details, protocols via dashboard
Email us:
- If you find errors we cannot fix via UI, email privacy@openassist.io
- We’ll correct inaccuracies within 15 days
6.5 Right to Opt Out of Marketing
Unsubscribe from promotional emails:
Immediate opt-out:
- Click “Unsubscribe” link at the bottom of any marketing email
- Preferences updated in Brevo within 24 hours
Dashboard settings:
- Toggle “Receive marketing emails” off in account settings (if we add this feature)
Email us:
- Send “Unsubscribe” request to preferences@openassist.io
Note: You cannot opt out of transactional emails (billing, security alerts—required for account management).
6.6 Right to Restrict Processing
Limit how we use your data:
If you believe data is inaccurate or processing is unlawful:
- Email privacy@openassist.io with your concern
- We’ll restrict processing (e.g., stop using data for analytics) while investigating
- You retain access to the Service (unless restriction prevents core functionality)
6.7 Right to Object to Processing
Object to specific data uses:
You can object to:
- Marketing: Opt out via unsubscribe links or email preferences@openassist.io
- Analytics: Disable Google Analytics via cookie consent banner
You cannot object to:
- Service provision: Processing required to operate OpenAssist (authentication, billing, agent management)
- Legal compliance: Processing required by law (tax records, fraud prevention)
7. GDPR COMPLIANCE (EU/EEA Users)
If you are located in the European Union (EU), European Economic Area (EEA), United Kingdom (UK), or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR).
7.1 Legal Basis for Processing
We process your personal data under the following legal bases:
| Data Type | Legal Basis | GDPR Article |
|---|---|---|
| Account info, subscription, service usage | Contract (necessary to provide the Service) | Art. 6(1)(b) |
| Payment processing | Contract (necessary for billing) | Art. 6(1)(b) |
| Marketing emails | Consent (opt-in via signup or explicit consent) | Art. 6(1)(a) |
| Analytics (Google Analytics) | Legitimate interest (improve service, with opt-out available) | Art. 6(1)(f) |
| Fraud prevention, security | Legitimate interest (protect users and our business) | Art. 6(1)(f) |
| Legal compliance | Legal obligation (tax records, law enforcement requests) | Art. 6(1)(c) |
7.2 Data Transfers Outside the EU
Your data may be transferred to the United States:
OpenAssist’s infrastructure is primarily US-based:
- Supabase: Data centers in US (with EU region option if selected)
- DigitalOcean: You choose droplet region (Amsterdam, Frankfurt available for EU users)
- Vercel: US-based, with global CDN
- Stripe: US company, GDPR-compliant data processing
Transfer safeguards:
- Standard Contractual Clauses (SCCs): EU-approved contracts with US vendors (Supabase, Stripe, Google, Brevo)
- Adequacy decisions: UK and Switzerland have adequacy decisions allowing data flows
- EU hosting option: You can deploy agents in EU DigitalOcean regions (Amsterdam, Frankfurt) to keep agent data in the EU
7.3 Data Protection Officer (DPO)
For GDPR inquiries:
- Email: dpo@openassist.io (or privacy@openassist.io)
- We will designate a DPO if we exceed GDPR thresholds (currently not required for our scale)
7.4 Right to Lodge a Complaint
If you believe we’ve violated GDPR, you may:
- Contact us first: privacy@openassist.io (we’ll resolve issues promptly)
- File a complaint with your local Data Protection Authority (DPA):
- Find your DPA: https://edpb.europa.eu/about-edpb/about-edpb/members_en
- Example: CNIL (France), ICO (UK), BfDI (Germany)
7.5 Consent Withdrawal
You can withdraw consent at any time (for marketing emails, analytics cookies):
- Effect: We stop processing data for that purpose
- Does not affect past processing (while consent was valid)
- Does not affect processing based on other legal bases (contract, legal obligation)
To withdraw consent:
- Marketing emails: Unsubscribe link or email preferences@openassist.io
- Analytics cookies: Disable via cookie consent banner or browser settings
8. CCPA COMPLIANCE (California Residents)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).
8.1 Categories of Personal Information We Collect
| Category | Examples | Collected? |
|---|---|---|
| Identifiers | Name, email, IP address, user ID | ✅ Yes |
| Commercial information | Subscription plan, billing history, payment method | ✅ Yes |
| Internet activity | Page views, clicks, usage logs (via Google Analytics) | ✅ Yes |
| Geolocation | Approximate location (city/country from IP), droplet region | ✅ Yes |
| Inferences | User preferences, behavior patterns (from analytics) | ✅ Yes |
| Sensitive personal information | API keys (encrypted, inaccessible to us) | ✅ Yes (but secured) |
| Biometric information | None | ❌ No |
| Health data | None | ❌ No |
| Financial account details | None (Stripe handles payment, we don’t store card numbers) | ❌ No |
8.2 How We Use Personal Information
We use your data to:
- Provide the Service (agent deployment, dashboard, billing)
- Improve the Service (analytics, debugging)
- Communicate with you (emails, notifications)
- Prevent fraud and enforce Terms
We do NOT sell your personal information. (See CCPA § 1798.120)
8.3 Your California Privacy Rights
Right to Know (CCPA § 1798.100):
- Request what personal information we’ve collected about you (see Section 6.1)
Right to Delete (CCPA § 1798.105):
- Request deletion of your personal information (see Section 6.2)
- Exceptions: Legal compliance, fraud prevention, financial records (7-year retention)
Right to Correct (CCPA § 1798.106):
- Request correction of inaccurate information (see Section 6.4)
Right to Opt Out of Sale/Sharing (CCPA § 1798.120):
- We do NOT sell your personal information—opt-out not applicable
- We do NOT share data for cross-context behavioral advertising
Right to Limit Use of Sensitive Information (CPRA § 1798.121):
- We only use sensitive information (API keys) for Service provision (not for analytics or marketing)
- No action needed—already limited to essential purposes
Right to Non-Discrimination (CCPA § 1798.125):
- We will NOT discriminate against you for exercising your rights
- No denial of service, different pricing, or degraded experience
8.4 How to Exercise Your California Rights
Submit a request:
- Email privacy@openassist.io with subject line “CCPA Request”
- Include:
- Your registered email address
- Specific right you’re exercising (know, delete, correct)
- Verification details (we may ask security questions)
Response timeline:
- Acknowledgment: Within 10 days
- Fulfillment: Within 45 days (may extend to 90 days if complex, with notice)
Verification process:
- We’ll verify your identity via email confirmation or security questions
- For sensitive requests (deletion), we may require additional verification
Authorized agents:
- You may designate someone to submit requests on your behalf
- Provide written authorization or power of attorney
8.5 Shine the Light Law (California Civil Code § 1798.83)
California residents may request information about personal information shared with third parties for direct marketing purposes.
OpenAssist does NOT share your data with third parties for their direct marketing.
If you want confirmation, email privacy@openassist.io with “Shine the Light Request” in the subject line.
8.6 Do Not Track (DNT) Signals
We do NOT currently respond to “Do Not Track” (DNT) browser signals.
Why? No industry standard exists for interpreting DNT signals. However:
- You can disable Google Analytics via our cookie consent banner
- You can block cookies via browser settings
9. COOKIES & TRACKING TECHNOLOGIES
9.1 What Are Cookies?
Cookies are small text files stored by your browser. We use cookies to:
- Keep you logged in (authentication)
- Remember your preferences (active agent selection)
- Analyze usage patterns (Google Analytics)
9.2 Types of Cookies We Use
Essential Cookies (Required)
| Cookie Name | Purpose | Duration | Can Opt Out? |
|---|---|---|---|
sb-auth-token | Supabase authentication session | 24 hours | ❌ No (required for login) |
sb-refresh-token | Keeps you logged in across sessions | 30 days | ❌ No (required for login) |
Browser localStorage (not cookies, but similar):
openclaw_active_instance: Remembers your last selected agent | Persistent | ✅ Yes (clear browser data)
Analytics Cookies (Optional)
| Cookie Name | Purpose | Duration | Can Opt Out? |
|---|---|---|---|
_ga | Google Analytics: Distinguishes users | 2 years | ✅ Yes (cookie banner) |
_ga_* | Google Analytics: Stores session state | 2 years | ✅ Yes (cookie banner) |
_gid | Google Analytics: Distinguishes users (short-term) | 24 hours | ✅ Yes (cookie banner) |
What Google Analytics tracks:
- Page views and navigation (which features you use)
- Session duration (how long you stay on the dashboard)
- Device and browser info (to optimize for your platform)
What Google Analytics does NOT track:
- Your identity (email, name)—data is pseudonymized
- Chat message content or AI prompts
- API keys or sensitive credentials
IP anonymization:
- Google Analytics anonymizes the last octet of your IP address (e.g., 192.168.1.XXX)
- Full IP address is never stored by Google
Marketing Cookies (Not Currently Used)
We do not currently use marketing/retargeting cookies (e.g., Facebook Pixel, Google Ads remarketing).
If we add them in the future:
- 30 days’ notice via email
- Explicit opt-in required (GDPR) or opt-out mechanism (CCPA)
- Updated Privacy Policy with details
9.3 Cookie Consent Banner
When you first visit OpenAssist:
EU/EEA/UK users (GDPR):
- Explicit consent required before non-essential cookies (analytics) are set
- Cookie banner appears: “We use cookies for authentication and analytics. [Accept All] [Essential Only] [Customize]”
- If you decline analytics, Google Analytics is not loaded
US/Non-EU users:
- Notice-based approach: Banner informs you of cookie use
- Analytics cookies load by default (you can opt out via banner or browser settings)
- Complies with CCPA (you can disable via “Do Not Sell My Personal Information” link)
Your choices:
- Accept All: All cookies enabled (authentication + analytics)
- Essential Only: Only required cookies (authentication)—Google Analytics disabled
- Customize: Choose which categories to enable/disable
Banner behavior:
- Appears on first visit (or after clearing cookies)
- Choice stored in localStorage (persists across sessions)
- Can revisit choices via “Cookie Preferences” link in footer
9.4 Managing Cookies
Browser controls:
- Chrome: Settings > Privacy > Cookies
- Firefox: Settings > Privacy > Cookies and Site Data
- Safari: Preferences > Privacy > Cookies
- Edge: Settings > Privacy > Cookies
Disable all cookies:
- Effect: You will be logged out and cannot use OpenAssist (authentication cookies required)
Disable analytics cookies only:
- Use our cookie consent banner to select “Essential Only”
- Or install Google Analytics Opt-out Add-on
Clear existing cookies:
- Browser settings > Clear browsing data > Cookies
- Effect: You’ll be logged out and need to sign in again
9.5 Third-Party Tracking
We do NOT use:
- Cross-site tracking pixels
- Advertising networks (Google Ads, Facebook Ads retargeting)
- Data brokers or affiliate tracking
- Browser fingerprinting
Third-party cookies from our vendors:
- Google Analytics: As described in Section 9.2
- Stripe: May set cookies during payment flow (governed by Stripe’s policy)
Social media embeds:
- We do not embed Facebook Like buttons, Twitter feeds, or similar tracking widgets
10. CHILDREN’S PRIVACY
OpenAssist is NOT intended for children under 18.
Our Terms of Service require users to be at least 18 years old. We do not knowingly collect personal information from minors.
COPPA Compliance (USA):
- Not applicable (we target adults, not children under 13)
If we discover a child’s account:
- Immediate termination of account
- Deletion of all associated data
- Notification to parent/guardian (if contact information is available)
Parents/Guardians:
If you believe your child has created an account, email privacy@openassist.io immediately. We’ll delete the account within 24 hours.
11. INTERNATIONAL DATA TRANSFERS
OpenAssist operates primarily in the United States. If you access the Service from outside the US, your data may be transferred to and processed in the US.
11.1 EU/EEA/UK/Switzerland → US Transfers
Data protection safeguards:
- Standard Contractual Clauses (SCCs): EU-approved contracts with US vendors (Supabase, Google, Stripe, Brevo)
- EU Data Hosting Option: Deploy agents in DigitalOcean EU regions (Amsterdam, Frankfurt) to keep agent data within the EU
- GDPR Compliance: All vendors are GDPR-compliant (data processing agreements in place)
UK transfers:
- UK government has issued an “adequacy decision” for US data transfers under the UK-US Data Bridge
- No additional safeguards required for UK → US transfers
Swiss transfers:
- Switzerland has an adequacy decision with the US (Privacy Shield 2.0 framework)
11.2 Other Jurisdictions
Brazil (LGPD):
- Brazilian users’ data may be transferred to the US (we’re US-based)
- LGPD allows international transfers if adequate safeguards exist (contracts with vendors, encryption)
Other countries:
- If your country restricts data transfers, you acknowledge that using OpenAssist involves transferring data to the US
- You consent to this transfer by using the Service
12. DATA BREACH NOTIFICATION
12.1 What Constitutes a Breach?
A data breach occurs when unauthorized parties gain access to:
- Personal information (email, name, IP addresses)
- Service data (tasks, agent configurations, chat logs)
- Credentials (passwords, API keys, tokens)
Not considered breaches:
- Authorized access by you or our support team (with your consent)
- Anonymized analytics data leaks (no PII)
- Public information (e.g., your agent’s public GitHub repo, if you choose to share it)
12.2 Notification Timeline
Within 72 hours of discovery, we will:
Email affected users with:
- What happened: Description of the breach (attack vector, date/time discovered)
- What data was compromised: Specific types of information accessed (email, tasks, etc.)
- What we’re doing: Immediate containment steps, security patches, forensic investigation
- What you should do: Recommended actions (change passwords, rotate API keys, monitor accounts)
Notify regulators (if required):
- EU/EEA: Report to lead Data Protection Authority within 72 hours (GDPR Art. 33)
- California: Report to Attorney General if >500 California residents affected (CCPA)
- Other jurisdictions: As required by local laws
12.3 Our Response Process
Immediate (0-24 hours):
- Detect & contain: Isolate affected systems, revoke compromised credentials
- Assess impact: Determine what data was accessed, how many users affected
- Preserve evidence: Log forensic data for investigation
Short-term (24-72 hours):
4. Notify users: Send breach notification emails
5. Notify regulators: File required reports (GDPR, CCPA)
6. Patch vulnerabilities: Fix security flaws, update systems
Long-term (72+ hours):
7. Investigation: Root cause analysis, third-party security audit (if needed)
8. Post-mortem: Document lessons learned, improve security measures
9. Ongoing monitoring: Enhanced detection for similar attacks
12.4 Your Responsibilities After a Breach
If notified of a breach, you should:
- Change passwords: Update your OpenAssist password and Google account password
- Rotate API keys: Generate new Anthropic/OpenAI keys, revoke old ones
- Monitor accounts: Watch for suspicious activity on linked services (Stripe, email)
- Enable 2FA: If we add two-factor authentication, enable it immediately
We will NOT:
- Ask you to “verify” your account via email links (phishing risk)
- Request your password or API keys (we never need these)
13. CONTACT & DATA PROTECTION
13.1 Privacy Contact
For all privacy-related inquiries:
- Email: privacy@openassist.io
- Response time: 3 business days for general inquiries, 30 days for formal data requests
- Subject line examples: “GDPR Data Access Request,” “CCPA Deletion Request,” “Cookie Opt-Out”
13.2 Data Subject Requests
To exercise your rights (access, delete, export, correct):
Step 1: Email us
- Send request to privacy@openassist.io
- Include your registered email address and specific request
Step 2: Verification
- We’ll verify your identity (email confirmation or security questions)
- For sensitive requests (deletion), additional verification may be required
Step 3: Fulfillment
- GDPR: 30 days (may extend to 90 days if complex, with notice)
- CCPA: 45 days (may extend to 90 days if complex, with notice)
- Other users: 30 days (best-effort basis)
No fee for first request (excessive/repetitive requests may incur reasonable administrative fees).
13.3 General Support
For non-privacy issues:
- Email: support@openassist.io
- Topics: Account help, billing questions, technical support
13.4 Legal Contact
For legal matters:
- Email: legal@openassist.io
- Topics: Subpoenas, court orders, law enforcement requests, arbitration notices
13.5 Physical Address (Mailing)
IANternet Media
[Your NJ Business Address]
[City, State, ZIP Code]
14. UPDATES TO THIS PRIVACY POLICY
14.1 When We Update This Policy
We may update this Privacy Policy when:
- New features are added that affect data collection (e.g., new integrations)
- Legal requirements change (new privacy laws, regulatory guidance)
- Third-party policies change (vendor updates to Supabase, Google Analytics, etc.)
- User feedback identifies ambiguities or missing information
Annual review: We review this policy at least once per year (even if no changes).
14.2 How We Notify You
Material changes (affecting your rights or data usage):
- Email notification 30 days in advance to all registered users
- Dashboard banner highlighting key changes (with link to full policy)
- Blog post explaining updates (if significant)
- Updated “Last Modified” date at the top of this page
Minor changes (typo fixes, clarifications, formatting):
- Updated “Last Modified” date only (no proactive notification)
- Changes take effect immediately upon posting
14.3 Acceptance of Changes
Continued use of OpenAssist after the effective date = acceptance of the updated policy.
If you disagree with changes:
- Email privacy@openassist.io to express concerns (we may address them)
- Cancel your subscription before the effective date to avoid being bound by new terms
- Request account deletion if you no longer wish to use the Service
Changes do not apply retroactively—previous versions govern past data processing.
14.4 Policy Version History
Current version: 1.0 (Effective February 10, 2026)
Previous versions: None (initial version)
15. ADDITIONAL PRIVACY INFORMATION
15.1 Automated Decision-Making
We do NOT use automated decision-making or profiling that significantly affects you:
- No AI-based credit scoring or eligibility decisions
- No automated content moderation (you control your agent)
- No behavioral predictions influencing service access
Google Analytics inferences (e.g., “this user prefers Protocol X”) are used only for aggregate analytics, not individual decisions.
15.2 Sensitive Personal Information
What we consider sensitive:
- API keys (Anthropic, OpenAI, DigitalOcean tokens)
- Payment information (stored by Stripe, not us)
- Chat logs (may contain personal thoughts, business data)
How we protect sensitive data:
- Encryption at rest and in transit (AES-256, TLS 1.3)
- Access controls: Only you can access your data (via dashboard or SSH)
- No training: We never use your data to train AI models
- Immediate deletion: Upon account cancellation, sensitive data is destroyed
15.3 Marketing & Communications
What you’ll receive:
Transactional (mandatory):
- Welcome email (account creation)
- Billing notifications (payment success/failure, renewal reminders)
- Security alerts (suspicious login, password change)
- Service updates (critical bug fixes, planned maintenance)
Marketing (optional, opt-in):
- Product updates and new features
- Tips and tutorials for using OpenAssist
- Blog posts and industry insights
- Promotional offers (discounts, referral programs)
Frequency:
- Transactional: As needed (typically <5 per month)
- Marketing: ~2-4 per month (you control frequency via preferences)
Opt-out:
- Click “Unsubscribe” in any marketing email (instant)
- Email preferences@openassist.io
- Adjust settings in dashboard (if we add this feature)
15.4 Third-Party Links
Our dashboard may contain links to third-party sites:
- OpenClaw documentation (openclaw.ai)
- AI provider dashboards (Anthropic, OpenAI)
- DigitalOcean console
- Stripe billing portal
We are NOT responsible for:
- Privacy practices of third-party sites
- Content or security of external links
- Data collected by linked services
Before clicking external links, review their privacy policies.
15.5 Social Media
We do NOT:
- Embed social media widgets (Facebook Like, Twitter follow buttons)
- Share your data with social media platforms (unless you explicitly connect accounts)
If we add social features in the future:
- Explicit opt-in required (GDPR)
- Updated Privacy Policy with full disclosure
16. SUMMARY OF KEY POINTS
✅ What we collect: Email, payment info (via Stripe), service data (tasks, agents, chat logs), technical data (IP, browser), analytics (Google Analytics)
✅ How we use it: Provide service, improve features, send emails (transactional + marketing), prevent fraud
✅ Who we share with: Supabase (database), DigitalOcean (hosting), Vercel (dashboard), Stripe (payments), Google Analytics, Brevo (emails)—no data selling
✅ Your rights: Access, delete, export, correct, opt out of marketing, limit analytics (via cookie banner)
✅ Data deletion: Immediate upon account cancellation (no recovery)—backups retained 90 days (encrypted, inaccessible)
✅ Security: TLS encryption, AES-256 at rest, access controls, breach notification within 72 hours
✅ Compliance: GDPR (EU), CCPA (California), LGPD (Brazil)—international data transfers with safeguards
✅ Cookies: Essential (auth) + optional analytics (Google)—cookie banner for GDPR compliance
✅ Contact: privacy@openassist.io for all privacy requests (30-day response)
17. CONSENT & ACCEPTANCE
By using OpenAssist, you:
- Acknowledge you have read and understood this Privacy Policy
- Consent to the data practices described herein
- Agree to the collection, use, and sharing of your information as outlined
- Accept international data transfers (if outside the US)
If you do not agree, please do not create an account or use the Service.
Last Updated: February 10, 2026
Effective Date: February 10, 2026
Version: 1.0
Thank you for trusting OpenAssist with your data. We take your privacy seriously.
For questions or concerns, contact us at privacy@openassist.io.